Learn how AI can enhance security measures by detecting malicious assets, and safeguarding against vulnerabilities. Stay secure with advanced technology.
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Willem Van Zwieten
Data Science & Analytics Lead
Share
20
Jan 2022
The internet is huge and is expanding every day. While this has many positives for businesses, managing the potential risks in this environment can be daunting. The reality is that across the internet brands are susceptible to everything from brand abuse to phishing websites. So, how is it possible that organisations can keep track of the web-based assets that belong to them, and at the same time distinguish them from something that may only look like it’s theirs? Finding and verifying all of a company’s web assets across the entire internet is a massive undertaking. You essentially need to filter the whole internet and try to pick out what is relevant, and then set about detecting the risks – or even potential risks – within what you have found.
This isn’t a process that can be managed manually. The staff-hours alone would make this hugely prohibitive, and that’s without taking into account the potential margin for error. Instead, it requires a different approach, one based around automation. At Darktrace, my team and I work on exactly those kind of solutions. We’ve developed our own algorithms to define what distinguishes a client’s brand-owned site from everything else on the internet. We refer to that as a company’s Brand DNA. These special characteristics help us to predict and identify where any brand-related assets are across the entire internet, and how they should be investigated further. The concept of an organisation’s Brand DNA breaks down into two areas: what is unique by design and what is uniqueby comparison.
Unique by Design
All brands have different design elements that help set them apart from other brands. This can be everything from their name and logo, to the different fonts and colours they use in all their communications and websites. By ingesting this data into our algorithms we are able to scan the internet for any web-based assets that may be relevant to a company, based on these key brand elements. While the elements of ‘unique by design’ are relatively easily understandable by humans, no organisations want to have their time taken up manually searching through millions of images every day in order to help them locate the web properties that might belong to their organisation.
Unique by Comparison
Conversely, ‘unique by comparison’ focuses more on the elements that a human would probably not be able to figure out by themselves. As we suggest potential new domains to customers, we build up a pool of assets. Automation allows us to find patterns in these assets that might not be immediately obvious to humans, such as elements of metadata,nameserver details, or even where a website is hosted. Although unique by design is more about what you actually see on a website and unique by comparison focuses on the back-end, in reality there are overlaps and the two things feed into each other.
As a very basic example: if a domain is hosted on nameserver where other company assets are hosted, AND the company logo is on the page, then the chances are this domain is a company-owned asset. In effect, the two approaches strengthen each other. By analysing all these details together, our algorithms can increasingly accurately score how likely an asset is to be owned by a company. I should add here that unique by comparison is based on comparing a lot of features at once, so it is often not as clear cut as the above example.
Combining Humans and AI
Ultimately, automating the process in this way helps to create a minimal-touch process for companies. The algorithms do all the filtering, enabling the creation of a much-reduced list of assets for the company to look through. Basically, we’re able to break down that list to avery small percentage of the internet that they actually need to look at and then analyse the risk those assets poseto the organisation.
We also use something which we internally label “AI2”(artificial intelligence with analyst interaction). This essentially means we’re adding a human layer to the automated process, for both input and output checks. While the algorithms do all the heavy lifting and aid scalability, the human element allows us to finetune or dive deeper into certain automated findings.
Detecting Malicious Assets
While the algorithms are principally focused on establishing a brand’s attack surface, a useful byproduct is that they can also locate malicious assets, such as potential phishing sites. For example, if something looks like it belongs to the customer, but doesn’t actually belong inside their directdigital infrastructure, then clearly there is an increased likelihood that it is either a brand abuse or phishing site.
On top of this, as part of our search process we can also automatically create combinations of possible URLs that cover common search errors such as typos or “fat finger”errors within brand names, and then hunt for those – clearly the likelihood of these URLs being rogue sites is greatly enhanced.
The Clearest View of the Attack Surface
By combining all these elements, companies are able to get the most complete view of their potential attack surface.And with the use of enhanced automation techniques they can do so with minimum effort. From this position companies are able to easily and quickly home in on the genuine items, and the areas that pose them the most risk. They can then use the resulting list to form the foundations from which they can apply the rest of their security strategy.
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Securing AI: Analysis of the Complete Security Stack with Governance and Controls
As organizations accelerate AI adoption, securing AI requires more than governance policies or model guardrails. This guide explores how security leaders can build a defense-in-depth strategy that addresses AI across governance, identity, data security, secure development, runtime monitoring, and incident response. Drawing on recent guidance from NIST and the Five Eyes alliance, it outlines the core capabilities organizations should prioritize to securely adopt AI while reducing operational and cyber risk.
Testing a Prompt injection Attack Against an Enterprise AI Agent
Darktrace tested whether an enterprise AI agent could be targeted through a hidden prompt injection delivered by email, and whether behavioral email analysis could detect and respond to the attack before it reached the agent. The experiment found that although the email contained no malware, malicious links, or sender reputation indicators, Darktrace / EMAIL identified the attack based on anomalous language and behavioral context.
Extending AI Security Visibility with Darktrace and Microsoft Agent 365
Darktrace is integrating with Microsoft Agent 365 to bring behavior-based AI agent risk signals directly into the Microsoft 365 Admin Center. The integration gives security teams a more unified view of agent activity, helping them identify anomalous behavior, investigate potential risks, and manage AI agents more efficiently across Microsoft environments.
Securing AI: Analysis of the Complete Security Stack with Governance and Controls
Key takeaways
Protecting enterprise AI requires defense in depth: Organizations should combine governance, identity and access controls, data security, secure development, runtime monitoring, behavioral detection, containment, and incident response rather than rely on a single control.
Agentic AI expands enterprise risk beyond the model: Autonomous agents interact with tools, APIs, identities, data, and other agents, creating identity, behavioral, structural, and accountability risks that can propagate across trusted systems.
An effective AI security stack spans multiple layers: Security teams should evaluate governance and visibility, identity and agent controls, data protection, secure MLOps and LLMOps, runtime security, and response and recovery capabilities.
Security controls should develop alongside enterprise AI adoption: Organizations should establish ownership, visibility, access controls, testing, monitoring, and recovery capabilities while using behavior-based detection and containment to address risks that static policies may not reveal.
Why traditional cybersecurity approaches are not enough for AI
AI adoption outpaces most security programs’ ability to adapt. That gap is now one of the most consequential sources of cyber risk facing enterprises. As organizations embed generative and agentic AI into development workflows, business operations, and security tooling itself, the question is no longer whether AI will introduce risk. The question is whether organizations understand where that risk actually lives and how to manage it operationally.
Two recent pieces of guidance underscore this shift:
The upcoming Cybersecurity Framework Profile for AI from NIST
The Five Eyes government guidance on the careful adoption of agentic AI services
Taken together, they point to a critical conclusion. AI security cannot be reduced to model hardening or prompt filtering. It requires a defense in depth strategy that treats AI as both a new attack surface and a force multiplier for defense, while accounting for how AI fundamentally changes scale, speed, and autonomy.
Recent threat research suggests that today's cyber risk is driven less by initial compromise and more by an adversary's ability to blend into normal operations over time. AI systems create the same exposure in a new form: more autonomy, more scale, and more opportunities for risky behavior to blend into normal operations.
How NIST defines the three core pillars of AI security
The NIST profile organizes AI risk across three inseparable focus areas that span all cybersecurity functions, Secure, Defend and Thwart. These areas are not sequential. They exist simultaneously and must be addressed together.
Secure
This treats AI as an attack surface. It includes models, prompts, agents, pipelines, training and inference data, retrieval augmented generation corpora, and the AI supply chain itself. AI systems are opaque, probabilistic, and non-deterministic by design. Some vulnerabilities are inherent in how models are trained or how data is sourced. Traditional patching does not fully mitigate these risks. This is also where many enterprises are weakest today and, critically, where many security programs stop.
Defend
This is AI as a defensive force multiplier. AI can improve detection speed, scale, correlation, and response, but only if the right models are used and operationalized correctly. Machine-speed behavior-based detection, response and containment becomes critical in defending non-deterministic systems. Accuracy, explainability, governance, testing, validation, and integration into SOC workflows matter as much as capability. Without those controls, hallucination risk, over automation, and misplaced trust become security risks themselves.
Thwart
This treats AI as an adversarial accelerant. Threat actors are already using AI to generate targeted social engineering attacks, deepfakes, malware, and autonomous attack agents. Asymmetric warfare is highlighting faster vulnerability discovery and exploitation with a lag on patch development, testing and deployment.
How this looks in practice
Darktrace researchers observed scaled, automated exploitation of the React2Shell vulnerability within days of disclosure. A vulnerable cloud asset was exploited in under 120 seconds of being deployed. Darktrace research team observed an AI/LLM-generated malware sample used in exploitation activity tied to React2Shell. The significance isn't novelty. It is that AI lowers the barrier to producing usable offensive tooling and compresses the time between experimentation and deployment.
Tactics are getting more and more creative in order to string together steps of an attack kill chain. This creates a dependency on behavior-based detection, autonomous investigation, autonomous containment, training, resilience investment, and recovery planning across the entire enterprise.
Why agentic AI fundamentally changes enterprise cyber risk
The Five Eyes guidance on agentic AI highlights material changes to the cyber risk profile of an organization. Unlike generative AI systems that produce content for human consumption, agentic AI systems reason, plan, and act autonomously across tools, data, and environments. That autonomy, combined with access to real systems, amplifies the impact of traditional cyber failures and introduces new system level risks that are difficult to predict, observe, and contain.
Risk in agentic systems does not live in the model alone. It emerges from interactions between models, prompts, memory, tools, APIs, identities, privileges, inter-agent trust relationships, and human assumptions baked into design. Vulnerabilities are often introduced through data, connectors, natural language interfaces, protocols, and drift by design.
In supply-chain incidents, attackers did not need sophisticated exploits to scale impact. They abused trusted systems built for automation and implicit access. Agentic AI inherits that model. Once a system can act across tools, data, and workflows, compromise propagates through trust relationships that were never designed for machine autonomy.
The major agentic AI risk classes include the following:
The identity control for non-human identities or autonomous agents makes it difficult to mitigate over-permissioning, limiting access, scope, and duration, as well as access hygiene
Agents are frequently over permissioned
Compromised tools inherit agent authority
Static secrets enable impersonation
Implicit trust between agents enables lateral movement
Design and configuration risks compound this, including privileges evaluated once at startup, poor segmentation, unvetted third party tools, reused authorization decisions outside their original context, and guardrail limitations.
Behavioral risk
Agents can optimize for goals in unsafe ways, misinterpret ambiguous intent, chain actions into unintended sequences, change behavior during evaluation, and exhibit deceptive or sycophantic responses.
Structural risk
Structural risk follows from agentic systems that are tightly coupled, multicomponent ecosystems. Failures can propagate across agents. Hallucinations cascade downstream. Resource exhaustion becomes systemic. Tool misuse enables indirect prompt injection and command execution. Rogue agents can poison peer agents through trust relationships.
Accountability
Accountability becomes unclear as autonomy increases. Autonomous agents assume human identity permissions, and humans should have clear ownership of these agents, but they don’t, and this model is flawed. Decision paths are opaque and non-deterministic. Logs are fragmented and difficult to interpret. Reproducing an incident will be impossible without explicit design for observability and forensics. An agent compromise is functionally an insider threat, often with better access and fewer behavioral constraints than a human.
What is the most effective way to protect enterprise AI?
The most effective way to protect enterprise AI is through a defense-in-depth strategy that combines governance, identity and access controls, data security, secure AI development, runtime monitoring, behavioral detection, containment, and incident response. No single control can address AI risk across models, agents, data, infrastructure, and enterprise environments.
Agentic AI runs on software, networks, identities, and data. It must be governed using the same foundational principles that have proven resilient under uncertainty, including secure by design, defense in depth, zero trust, least privilege, continuous monitoring, behavior-based advanced threat detection and containment, and incident response and recovery.
Core components to a Defense in depth Strategy for Securing the use of AI:
Strong, precise identity control plane to include an identity per agent (cryptographic, non‑shared)
Privilege monitoring and just‑in‑time access
Data Governance
Secure‑by‑default configurations
Security Posture Management
Zero Trust principles
Strong guardrails, deny‑by‑default policies, and isolation
Explicit instruction hierarchies and controlled context
Behavioral-based detection across entire enterprise to include inputs, tools, and outputs as well as AI used on the endpoint, across the network, cloud, SaaS, email, and OT
Runtime anomaly detection and goal‑drift detection
Autonomous containment to mitigate risk and minimize damage
Hard boundaries on autonomy and delegation
Testing, Evaluation, Validation and Verification
Determine when autonomous action and when human in the loop
Adversarial training and agent‑specific testing
Simulation, red teaming, and chaos testing
Kill‑switches, rollback, and containment mechanisms
Forensics data captures, interpretability, autonomous containment, and remediation/recovery plans
Until standards, tooling, and assurance methods mature, organizations should assume agentic AI systems will behave unexpectedly and design deployments around resilience, behavior-based detection, reversibility, and containment, not efficiency.
How security leaders should prepare for enterprise AI adoption
AI security is not model security alone. Data, pipelines, identities, and agents are first class assets. Many AI attacks succeed through standard cyber failures amplified by AI. Identity, data, and supply chain risk dominate. Behavior-based detection and response are critical, not optional. Logging, provenance, versioning, and forensics data capture of detections are mandatory because you cannot investigate or recover from AI incidents without them.
Risk will often be visible in behavior before it is clearly defined in policy or guidance. The same pattern has been seen in pre-CVE disclosure detection, where abnormal activity appears before the industry has named or described the vulnerability. AI systems introduce that uncertainty by design.
Security leaders should prioritize controls before AI is fully deployed, avoid generic AI security checklists, integrate AI risk into existing cyber programs, and mitigate the risk of non-deterministic technology with continuous oversight, monitoring, behavior analytics, anomaly detection, autonomous investigation, and autonomous containment.
Visibility has a different connotation with AI. Previously, audit logging worked for software/people, but with Generative AI-based systems, interpretability and explainability is difficult to understand, you cannot "undo" what has been done, or see the logic or control a chain of events. This is why behavioral-based detections and containment becomes critical.
What capabilities should every AI security program include?
If an organization asked “what must be in place before scaling AI?”:
AI Risk board and approval workflow
IAM + PAM for all AI services and agents
AI asset inventory
Prompt/output DLP with sanctioned AI access – This is not just pre- and post- filters, but behavior-based detections of semantic interface as well as behavior-based analysis of output with associated risk context.
Shadow AI identification
Secure MLOps – This is an entire paper itself
Runtime guardrails and tool restrictions
Including AI Gateway/SASE/Zero trust/
Runtime security with behavior-based detections
Complete visibility, monitoring, behavior analytics, anomaly detection, risk/intent/context evaluation of anomalies, autonomous investigation and autonomous containment of all AI assets across endpoint, network, SaaS, SASE, cloud, OT, email, and messaging platforms
Secure data pipelines and data governance
SOC workflow changes from malicious classification workflows to behavior-based detection workflows
Remediation plans for AI-related incidents
Layered Governance and Security Stack for Securing AI
An enterprise AI security stack should span six integrated layers: governance and visibility; identity, access, and agent control; data security and privacy; secure MLOps and LLMOps; runtime security; and response and recovery. These layers should work together rather than as a linear maturity sequence, with runtime controls helping manage risk as governance evolves.
These considerations do not need to be implemented in order. Runtime Detect and Respond will help mitigate risk while Governance, Visibility, and Identity mature.
Category
Tooling
Controls
Governance & Visibility
AI asset inventory / AI CMDB
Shadow AI discovery
SaaS discovery
AI usage on non-endpoint managed systems via network or cloud telemetry
MCP server/client usage via protocols
Browser telemetry
Gateway or SASE telemetry
Establish a risk board to set up controls
Mandatory registration of AI systems
Owner, data classification, intended use, and risk tier
Supplier disclosure requirements
Risk mitigation plan for AI adoption, innovation, or development
Identity, Access & Agent Control
Non-human autonomous agents should not have the full permissions associated with a human user.
IAM with workload identities
PAM for AI service accounts
Secrets management with short-lived tokens
Zero Trust principles
Identity, permission, and token hygiene
Unique identities per model, agent, and pipeline
Least privilege for tools, data, and APIs
Explicit approval for autonomous actions
Data Security & Privacy
Data classification and labeling
Enterprise DLP across endpoint, email, network, cloud, and SaaS
Forensics data capture after risky detections
Prompt-level DLP through behavior-based semantic analysis with risk and intent context
Input/interface analysis for risky data requests
Output analysis for sensitive data
Data integrity evaluation
Retention and redaction policies for prompts and responses
Secure MLOps / LLMOps
Secure CI/CD with AI-specific gates
Model registries with approval workflows
Dependency, container, and artifact scanning
SBOM/AIBOM generation
IaC security scanning
Security posture management
Misconfiguration identification
Hardening recommendations
Signed models and prompts
Versioned datasets, configurations, logging, and controls
Securing data pipelines
Controlled promotion
Quality assurance
Adversarial testing
Runtime Security
Securing runtime goes beyond guardrails and model firewalls to include behavior-based detections, response, and containment.
Detection, monitoring, and SOC integration
Centralized visibility into prompts, outputs, and tool calls
AI-specific detections
Behavior-based detection for AI usage patterns
Model drift and behavior monitoring
Autonomous containment
Behavior-based detection of model inputs and outputs
Prompt injection detection
Model manipulation, including jailbreaking, poisoning, and related attacks
Sensitive data access attempts
Behavior-based detection across low-code agents, high-code agents, MCP clients and servers, endpoint, network, cloud, email, SaaS, SASE, IoT, and OT
Policy enforcement between users, models, tools, agents, SaaS models/tools, and MCP servers/clients
Risk, intent, and context evaluation for detections and response actions
Response & Recovery
Autonomous containment
AI-assisted playbooks
Forensics data capture for AI-related events
Model rollback mechanisms
Backup and restore for models and datasets
Kill switch for agents
Autonomous response to agents performing risky behaviors
Model and dataset rollback
Remediation plans
Tabletop exercises
Supplier coordination plans
Post-incident AI performance validation
AI security requires continuous visibility and behavioral detection
AI changes how fast systems move, how decisions are made, and how risk propagates. It does not change the fundamentals of security. Organizations that succeed will be the ones that apply those fundamentals rigorously, assume failure, and build systems that can detect, contain, and recover when AI behaves in ways they did not anticipate. Security is not what AI is allowed to do. It is whether the organization can understand, trust, and control what AI actually does in practice.
Take this guidance to understand different initiatives that organizations should be considering. Securing AI is the most critical component to AI safety. As organizations invest more in AI adoption, they should be investing in security in order to mitigate the risk of AI adoption. Organizations should be evaluating their governance and security stack to include well-integrated tools that are deployed, tested, operationalized and embedded within security workflows. While organizations mature in governance, visibility and identity access management, they should be investing in behavior-based detection and autonomous containment to mitigate AI risk.
See how Darktrace / SECURE AI can strengthen the visibility and runtime security layers of your broader AI security program.
Ransomware is a multi-stage attack that requires detecting and containing malicious behavior throughout the attack lifecycle rather than focusing only on malware signatures or the encryption stage.
Ransomware operators can enter through phishing, exposed services, stolen credentials, and legitimate administrative tools, then move laterally and exfiltrate data before encryption, making behavior-based detection increasingly important.
Security teams should evaluate whether defenses can connect signals across initial access, command and control, lateral movement, data exfiltration, and encryption rather than treating each stage as an isolated event.
Behavioral detection, AI-led investigation, and targeted autonomous response can help security teams identify anomalous activity earlier and contain ransomware while limiting unnecessary disruption to normal business operations.
Ransomware gets its name by commandeering and holding assets ransom, extorting their owner for money in exchange for discretion and full cooperation in returning exfiltrated data and providing decryption keys to allow business to resume.
In this series, we break down this huge topic step by step. Ransomware is a multi-stage problem, requiring a multi-stage solution that autonomously and effectively contains the attack at any stage. Read on to discover how Self-Learning AI and Autonomous Response stops ransomware in its tracks.
Stage 1: How ransomware attacks begin through email
Email-based ransomware attacks often begin with a convincing message designed to steal credentials, deliver malware, or trigger a malicious action. Behavioral AI can identify deviations in sender, recipient, content, and account activity, helping detect compromised suppliers and previously unseen phishing infrastructure that signature- and reputation-based controls may miss. Well-researched, targeted, legitimate-looking emails are aimed at employees attempting to solicit a reaction: a click of a link, an opening of an attachment, or persuading them to divulge credentials or other sensitive information.
Gateways: Stops what has been seen before
Most conventional email tools rely on past indicators of attack to try and spot the next threat. If an email comes in from a blocklisted IP address or email domain, and uses known malware that has previously been seen in the wild, the attack may be blocked.
But the reality is, attackers know the majority of defenses take this historical approach, and so constantly update their attack infrastructure to bypass these tools. By buying new domains for a few pennies each, or creating bespoke malware with just small adaptions to the code, they can outpace and outsmart the legacy approach taken by a typical email gateway.
Real-world example: Supply chain phishing attack
By contrast, Darktrace’s evolving understanding of ‘normal’ for every email user in the organization enables it to detect subtle deviations that point to a threat – even if the sender or any malicious contents of the email are unknown to threat intelligence. This is what enabled the technology to stop an attack that recently targeted McLaren Racing, with emails sent to a dozen employees in the organization each containing a malicious link. This possible precursor to ransomware bypassed conventional email tools – largely because it was sent from a known supplier – however Darktrace recognized the account hijack and held the email back.
Figure 1: A snapshot of Darktrace’s Threat Visualizer surfacing the malicious email
Stage 2: How ransomware exploits servers and remote access
Server-side ransomware intrusion typically exploits exposed services, vulnerable systems, stolen credentials, or poorly secured remote access such as RDP. Because attackers may use legitimate credentials and administration tools, behavioral detection is needed to identify unusual access patterns, rare external connections, and activity that does not fit the affected server’s normal behavior.
A number of vulnerabilities against such Internet-facing servers and systems have been disclosed this year, and for attackers, targeting and exploiting public-facing infrastructure is easier than ever – scanning the Internet for vulnerable systems is made simple with tools like Shodan or MassScan.
Attackers may also achieve initial intrusion via RDP brute-forcing or stolen credentials, with attackers often reusing legitimate credentials from previous data dumps. This has much higher precision and is less noisy than a classic brute-force attack.
A lot of ransomware attacks use RDP as an entry vector. This is part of a wider trend of ‘Living off the Land’: using legitimate off-the-shelf tools (abusing RDP, SMB1 protocol, or various command line tools WMI or Powershell) to blur detection and attribution by blending in with typical administrator activity. Ensuring that backups are isolated, configurations are hardened, and systems are patched is not enough – real-time detection of every anomalous action is needed.
Antivirus, firewalls and SIEMs
In cases of malware downloads, endpoint antivirus will detect these if, and only if, the malware has been seen and fingerprinted before. Firewalls typically require configuration on a per-organization basis, and often need to be modified based on the needs of the business. If the attack hits the firewall where a rule or signature does not match it, again, it will bypass the firewall.
SIEM and SOAR tools also look for known malware being downloaded, leverage pre-programmed rules and use pre-programmed responses. While these tools do look for patterns, these patterns are defined in advance, and this approach relies on a new attack to have sufficiently similar traits to attacks that have been seen before.
Real-world example: Dharma ransomware
Darktrace detected a targeted Dharma ransomware attack against a UK organization exploiting an open RDP connection through Internet-facing servers. The RDP server began receiving a large number of incoming connections from rare IP addresses on the Internet. It is highly likely that the RDP credential used in this attack had been compromised at a previous stage – either via common brute-force methods, credential stuffing attacks, or phishing. Indeed, a technique growing in popularity is to buy RDP credentials on marketplaces and skip to initial access.
Figure 2: The model breaches that fired over the course of this attack, including anomalous RDP activity
Unfortunately, in this case, without Autonomous Response installed, the Dharma ransomware attack continued until its final stages, where the security team were forced into the heavy-handed and disruptive action of pulling the plug on the RDP server midway through encryption.
Stage 3: How ransomware establishes command and control
After gaining access, ransomware operators establish command-and-control channels to manage compromised devices, deliver additional tools, and prepare for later stages. AI can identify C2 activity by correlating weak signals such as rare destinations, unusual connection timing, unexpected downloads, and behavior that differs from the organization’s established patterns.
Attackers can adapt malware functionality with an assortment of ready-made plug-ins, allowing them to lie low inside the business undetected. More modern and sophisticated ransomware is able to adapt by itself to the surrounding environment, and operate autonomously, blending in to regular activity even when cut off from its command and control server. These ‘self-sufficient’ ransomware strains pose a big problem for traditional defenses reliant on stopping threats solely on the grounds of its malicious external connections.
Viewing connections in isolation vs understanding the business
Conventional security tools like IDS and firewalls tend to look at connections in isolation rather than in the context of previous and potentially relevant connections, making command and control very difficult to spot.
IDS and firewalls may block ‘known-bad’ domains or use some geo-blocking, but this is where an attacker would likely leverage new infrastructure.
These tools also don’t tend to analyze for things like the periodicity, such as whether a connection is beaconing at a regular or irregular interval, or the age and rarity of the domain in the context of the environment.
With Darktrace’s evolving understanding of the digital enterprise, suspicious C2 connections and the downloads which follow them are spotted, even when conducted using regular programs or methods. The AI technology correlates multiple subtle signs of threat – a small subset of which includes anomalous connections to young and/or unusual endpoints, anomalous file downloads, incoming remote desktop, and unusual data uploads and downloads.
Once they are detected as a threat, Darktrace's Autonomous Response halts these connections and downloads, while allowing normal business activity to continue.
Real-world example: WastedLocker attack
When a WastedLocker ransomware attack hit a US agricultural organization, Darktrace immediately detected the initial unusual SSL C2 activity (based on a combination of destination rarity, JA3 unusualness and frequency analysis). Darktrace (on this occasion configured in passive mode, and therefore not granted permission to take autonomous action) suggested instantly blocking the C2 traffic on port 443 and parallel internal scanning on port 135.
Figure 3: The Threat Visualizer reveals the action Darktrace would have taken
When beaconing was later observed to bywce.payment.refinedwebs[.]com, this time over HTTP to /updateSoftwareVersion, Darktrace escalated its response by blocking the further C2 channels.
Stage 4: How ransomware moves laterally through a network
Ransomware moves laterally as attackers scan the environment, access additional devices, obtain higher privileges, and search for valuable systems and data. Behavioral AI can detect unusual SMB, RDP, SSH, scanning, and credential activity, while targeted autonomous response can restrict suspicious connections before the intrusion spreads further.
Modern ransomware has built-in functions that allow it to search automatically for stored passwords and spread through the network. More sophisticated strains are designed to build themselves differently in different environments, so the signature is constantly changing and it’s harder to detect.
Legacy tools: A blunt response to known threats
Because they rely upon static rules and signatures, legacy solutions struggle to prevent lateral movement and privilege escalation without also impeding essential business operations. Whilst in theory, an organization leveraging firewalls and NAC internally with proper network segmentation and a perfect configuration could prevent cross-network lateral movement, maintaining a perfect balance between protective and disruptive controls is near impossible.
Some organizations rely on Intrusion Prevent Systems (IPS) to deny network traffic when known threats are detected in packets, but as with previous stages, novel malware will evade detection, and this requires the database to be constantly updated. These solutions also sit at the ingress/egress points, limiting their network visibility. An Intrusion Detection System (IDS) may sit out-of-line, but doesn’t have response capabilities.
A self-learning approach
Darktrace’s AI learns ‘self’ for the organization, enabling it to detect suspicious activity indicative of lateral movement, regardless of whether the attacker uses new infrastructure or ‘lives off the land’. Potential unusual activity that Darktrace detects includes unusual scanning activity, unusual SMB, RDP, and SSH activity. Other models that fire at this stage include:
Suspicious Activity on High-Risk Device
Numeric EXE in SMB Write
New or Uncommon Service Control
Autonomous Response then takes targeted action to stop the threat at this stage, blocking anomalous connections, enforcing the infected device’s ‘pattern of life’, or enforcing the group ‘pattern of life’ – automatically clustering devices into peer groups and preventing a device from doing anything its peer group hasn’t done.
Where malicious behavior persists, and only if necessary, Darktrace will quarantine an infected device.
Real-world example: Unusual chain of RDP connections
At an organization in Singapore, one compromised server led to the creation of a botnet, which began moving laterally, predominantly by establishing chains of unusual RDP connections. The server then started making external SMB and RPC connections to rare endpoints on the Internet, in an attempt to find further vulnerable hosts.
Other lateral movement activities detected by Darktrace included the repeated failing attempts to access multiple internal devices over the SMB file-sharing protocol with a range of different usernames, implying brute-force network access attempts.
Figure 5: Darktrace’s Cyber AI Analyst reveals suspicious TCP scanning followed by a suspicious chain of administrative RDP connections
Stage 5: How ransomware exfiltrates data before encryption
Many ransomware attacks steal data before encryption so attackers can threaten disclosure as well as operational disruption. Behavioral detection can surface unusual transfers, rare cloud-storage destinations, and low-and-slow exfiltration that may remain within static volume thresholds, giving defenders an opportunity to contain the attack before double extortion succeeds.
Modern ransomware variants also look for cloud file storage repositories such as Box, Dropbox, and others.
Many of these incidents aren’t public, because if IP is stolen, organizations are not always legally required to disclose it. However, in the case of customer data, organizations are obligated by law to disclose the incident and face the additional burden of compliance files – and we’ve seen these mount in recent years (Marriot, $23.8 million; British Airways, $26 million; Equifax, $575 million). There’s also the reputational blow associated with having to inform customers that a data breach has occurred.
Legacy tools: The same old story
For those that have been following, the narrative by now will sound familiar: to stop a ransomware attack at this stage, most defenses rely on either pre-programmed definitions of 'bad' or have rules constructed to combat different scenarios put organizations in a risky, never-ending game of cat and mouse.
A firewall and proxy might block connections based on pre-programmed policies based on specific endpoints or data volumes, but it’s likely an attacker will ‘live off the land’ and utilize a service that is generally allowed by the business.
The effectiveness of these tools will vary according to data volumes: they might be effective for ‘smash and grab’ attacks using known malware, and without employing any defense evasion techniques, but are unlikely to spot ‘low and slow’ exfiltration and novel or sophisticated strains.
On the other hand, because by nature it involves a break from expected behavior, even less conspicuous, low and slow data exfiltration is detected by Darktrace and stopped with Darktrace's Autonomos Response. No confidential files are lost, and attackers are unable to extort a ransom payment through blackmail.
Real-world example: Unusual chain of RDP connections
It becomes more difficult to find examples of Darktrace stopping ransomware at these later stages, as the threat is usually contained before it gets this far. This is the double-edged sword of effective security – early containment makes for bad storytelling! However, we can see the effects of a double extortion ransomware attack on an energy company in Canada. The organization had the Enterprise Immune System but no Darktrace, and without anyone actively monitoring Darktrace’s AI detections, the attack was allowed to unfold.
The attacker managed to connect to an internal file server and download 1.95TB of data. The device was also seen downloading Rclone software – an open-source tool, which was likely applied to sync data automatically to the legitimate file storage service pCloud. Following the completion of the data exfiltration, the device ‘serverps’ finally began encrypting files on 12 devices with the extension *.06d79000. As with the majority of ransomware incidents, the encryption happened outside of office hours – overnight in local time – to minimize the chance of the security team responding quickly.
It should be noted that the exact order of the stages 3–5 above is not set in stone, and varies according to attack. Sometimes data is exfiltrated and then there is further lateral movement, and additional C2 beaconing. This entire period is known as the ‘dwell time’. Sometimes it takes place over only a few days, other times attackers may persist for months, slowly gathering more intel and exfiltrating data in a ‘low and slow’ fashion so as to avoid detection from rule-based tools that are configured to flag any single data transfer over a certain threshold. Only through a holistic understanding of malicious activity over time can a technology spot this level of activity and allow the security team to remove the threat before it reaches the latter and most damaging stages of ransomware.
Stage 6: How AI can stop ransomware encryption
At the encryption stage, ransomware attempts to make files and systems unavailable, often using tools or protocols that may otherwise appear legitimate. AI-led autonomous response can recognize abnormal file-access and connection behavior, then enforce a device’s normal pattern of activity or block only the malicious action to limit disruption.
Using either symmetric encryption, asymmetric encryption, or a combination of the two, attackers attempt to render as much data unusable in the organization’s network as they can before the attack is detected.
As the attackers alone have access to the relevant decryption keys, they are now in total control of what happens to the organization’s data.
Pre-programmed response and disruption
There are many families of tools that claim to stop encryption in this manner, but each contain blind spots which enable a sophisticated attacker to evade detection at this crucial stage. Where they do take action, it is often highly disruptive, causing major shutdowns and preventing a business from continuing its usual operations.
Internal firewalls prevent clients from accessing servers, so once an attacker has penetrated to servers using any of the techniques outlined above, they have complete freedom to act as they want.
Similarly, antivirus tools look only for known malware. If the malware has not been detected until this point, it is highly unlikely the antivirus will act here.
Stopping encryption autonomously
Even if familiar tools and methods are used to conduct it, Autonomous Response can enforce the normal ‘pattern of life’ for devices attempting encryption, without using static rules or signatures. This action can be taken independently or via integrations with native security controls, maximizing the return on other security investments. With a targeted Autonomous Response, normal business operations can continue while encryption is prevented.
Stage 7: How ransomware attacks reach extortion
The ransom note marks the point at which the attacker makes the extortion demand explicit, usually offering a decryption key or nondisclosure in exchange for payment. Modern extortion may also involve stolen data, destroyed backups, domain hijacking, or direct harassment, so encryption is no longer the only path to a ransom demand.
All of the stages up until this point represent a typical, traditional ransomware attack. But ransomware is shifting from indiscriminate encryption of devices to attackers targeting business disruption in general, using multiple techniques to hold their victims to ransom. Additional methods of extortion include not only data exfiltration, but corporate domain hijack, deletion or encryption of backups, attacks against systems close to industrial control systems, targeting company VIPs… the list goes on.
Sometimes, attackers will just skip straight from stage 2 to 6 and jump straight to extortion. Darktrace recently stopped an email attack which showed an attacker bypassing the hard work and attempting to jump straight to extortion in an email. The attacker claimed to have compromised the organization’s sensitive data, requesting payment in bitcoin for its same return. Whether or not the claims were true, this attack shows that encryption is not always necessary for extortion, and this type of harassment exists in multiple forms.
Figure 6: Darktrace holds back the offending email, protecting the recipient and organization from harm
As with the email example we explored in the first post of this series, Darktrace/Email was able to step in and stop this email where other email tools would have let it through, stopping this potentially costly extortion attempt.
Whether through encryption or some other kind of blackmail, the message is the same every time. Pay up, or else. At this stage, it’s too late to start thinking about any of the options described above that were available to the organization, that would have stopped the attack in its earliest stages. There is only one dilemma. “To pay or not to pay” – that is the question.
Often, people believe their payment troubles are over after the ransom payment stage, but unfortunately, it’s just beginning to scratch the surface…
Stage 8: How AI supports ransomware investigation and clean-up
Ransomware clean-up begins with reconstructing how the intrusion started, which systems were affected, and which controls failed to stop it. AI-led investigation can connect activity across the attack timeline, helping security teams identify the initial access point, understand attacker movement, prioritize remediation, and reduce the risk of reinfection.
Legacy tools largely fail to shed light on the vulnerabilities which allowed the initial breach. Like searching for a needle in an incomplete haystack, security teams will struggle to find useful information within the limited logs offered by firewalls and IDSs. Antivirus solutions may reveal some known malware but fail to spot novel attack vectors.
With Darktrace’s Cyber AI Analyst, organizations are given full visibility over every stage of the attack, across all coverage areas of their digital estate, taking the mystery out of ransomware attacks. They are also able to see the actions that would have been taken to halt the attack by Darktrace's Autonomous Response.
Ransomware recovery involves restoring systems and data, validating that the threat has been removed, and returning operations to a trusted state. Recovery may continue even after a ransom is paid because decryptors can fail and files may remain damaged, making early detection, containment, tested backups, and incident readiness essential.
The organization begins attempts to return its digital environment to order. Even if it has paid for a decryption key, many files may remain encrypted or corrupted. Beyond the costs of the ransom payment, network shutdowns, business disruption, remediation efforts, and PR setbacks all incur hefty financial losses.
The victim organization may also suffer additional reputation costs, with 66% of victims reporting a significant loss of revenue following a ransomware attack, and 32% reporting losing C-level talent as a direct result from ransomware.
What is the best solution for preventing ransomware?
The solution category best suited to preventing ransomware is an AI-powered behavioral detection and autonomous response platform. This type of technology can identify unusual activity throughout the attack lifecycle and take targeted action before an intrusion progresses to data exfiltration, encryption, or extortion.
An effective ransomware prevention solution should:
Use behavioral analysis to identify known and previously unseen threats without relying solely on malware signatures, blocklists, or predefined attack rules.
Detect suspicious activity across email, network, cloud, identity, and endpoint environments rather than protecting only one stage of the ransomware attack chain.
Correlate signals such as unusual remote access, command-and-control communications, lateral movement, privilege escalation, and abnormal data transfers.
Take precise, real-time action against malicious activity while allowing unaffected users, devices, and business operations to continue normally.
Give security teams visibility into the complete attack sequence so they can investigate the initial intrusion, understand its impact, and strengthen defenses against future attacks.
Darktrace combines Self-Learning AI and Autonomous Response to deliver these capabilities. As the examples involving McLaren Racing, Dharma ransomware, WastedLocker, and unusual RDP activity demonstrate, this approach can identify and contain anomalous behavior that conventional gateways, firewalls, and signature-based controls may miss.
Conclusion
While the high-level stages described above are common in most ransomware attacks, the minute you start looking at the details, you realize every ransomware attack is different.
As many targeted ransomware attacks come through ransomware affiliates, the Tools, Techniques and Procedures (TTPs) displayed during intrusions vary widely, even when the same ransomware malware is used. This means that even comparing two different ransomware attacks using the same ransomware family, you are likely to encounter completely different TTPs. This makes it impossible to predict what tomorrow’s ransomware will look like.
This is the nail in the coffin for traditional tooling which is based on historic attack data. The above examples demonstrate that Self-Learning technology and Autonomous Response is the only solution that stops ransomware at every stage, across email and network.